Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /F /IM winword.exe
- '%WINDIR%\syswow64\taskkill.exe' /F /IM cmstp.exe
- '%WINDIR%\syswow64\cmd.exe' /c CmD < "%tmP%\aaaaaaaaaa.txt" & exit c
- %TEMP%\aaaaaaaaaa.txt
- %TEMP%\zjgzktlnuo.txt
- %TEMP%\aqrdyxjgueemflx.sct
- %APPDATA%\microsoft\network\connections\cm\ .cmp
- %TEMP%\aqrdyxjgueemflx.sct
- '62.##8.34.89':80
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c CmD < "%tmP%\aaaaaaaaaa.txt" & exit c' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmd.exe'
- '<SYSTEM32>\cmstp.exe' /s /ns "%TEMP%\zjGZKTLnuO.txt"